In any section of the Members tab, from the Actions menu, select Assign Assign

Managing Roles 12-19

5. To assign the membership rule, click Confirm Assign. Otherwise, click Cancel.

The Membership Rules page is displayed.

6. To revoke this membership rule, select the Delete option for the membership rule

that you want to remove from this role, and then click Delete. In the confirmation page click Conform Delete to remove the rules from this role.

12.5.2.8 Updating Data Object Permissions

Most permissions in Oracle Identity Manager concern data objects. You can define data objects as an internal object representation of tables in Oracle Identity Manager data model. In this model, the business logic is executed and responsible for inserting, updating, and deleting data from the data store. Permissions for these actions are defined at a role level. Depending on the table or data objects, these permissions can be categorized into the following: ■ Explicit InsertUpdateDelete Permission Required ■ Explicit Permission Not Required

12.5.2.8.1 Explicit InsertUpdateDelete Permission Required

Data objects for which explicit insert, update, or delete permission is required are the ones for which you must specify the insert, update, or delete permission by using Permissions from the Role Details page in Oracle Identity Manager Administrative and User Console to create, modify, and delete entities of these data objects. Consider the following example: A user belongs to multiple roles and a data object is assigned to both of these roles. Suppose you want to delete an entity of this data object type. To be able to do so, you must ensure that both roles have update permission on the data object. A user belongs to the Request Template Administrators and Request Administrators roles, and a data object is assigned to both of these roles. Suppose you want to delete an entity of this data object type. To be able to do so, you must ensure that both the Request Template Administrators and Request Administrators roles have update permission on the data object. Table 12–7 lists the data objects listed in this category and the entities of these data objects. Table 12–7 Data Objects Requiring Explicit InsertUpdateDelete Permissions Data Object Type Entities com.thortech.xl.dataobj.tcACS Organization.Lnk_Act_Svr com.thortech.xl.dataobj.tcADL Adapter Factory LogicSetVariable tasks com.thortech.xl.dataobj.tcADM Adapter Factory Inputoutput parameters com.thortech.xl.dataobj.tcADP Adapter Definitions com.thortech.xl.dataobj.tcADS Adapter Factory Stored Procedure tasks com.thortech.xl.dataobj.tcADT Adapter Tasks com.thortech.xl.dataobj.tcADU Adapter Factory WebServices tasks com.thortech.xl.dataobj.tcADV Adapter Factory Variables com.thortech.xl.dataobj.tcAPA Attestation Process Administrators com.thortech.xl.dataobj.tcARS Adapter Statuses com.thortech.xl.dataobj.tcATP Adapter Factory Parameter Task Table 12-20 Oracle Fusion Middleware Users Guide for Oracle Identity Manager com.thortech.xl.dataobj.tcDAV Data Object Adapter Variable com.thortech.xl.dataobj.tcDVT Event handlers associated with data objects com.thortech.xl.dataobj.tcEMD Email Definitions com.thortech.xl.dataobj.tcERR Error Message Definitions com.thortech.xl.dataobj.tcEVT Event Handlers com.thortech.xl.dataobj.tcGPY role Properties com.thortech.xl.dataobj.tcLKU Lookup Definitions com.thortech.xl.dataobj.tcLKV Lookup values for a lookup com.thortech.xl.dataobj.tcOBA Resource object authorizers com.thortech.xl.dataobj.tcODF Object To Process Data Flow com.thortech.xl.dataobj.tcODV Resource object Events com.thortech.xl.dataobj.tcOOD Resource Objects Organization Object Dependencies com.thortech.xl.dataobj.tcOUD Resource Objects User Object Dependencies com.thortech.xl.dataobj.tcPDF Process Integration Data Flow Mappings com.thortech.xl.dataobj.tcPKH Package Hierarchy com.thortech.xl.dataobj.tcPOC Access Policies Child Table Data com.thortech.xl.dataobj.tcPOF Policy parent data com.thortech.xl.dataobj.tcPOG roles defined on access policy com.thortech.xl.dataobj.tcPOL Access policy definition com.thortech.xl.dataobj.tcPOP Assigned Objects on access policies com.thortech.xl.dataobj.tcPRF Process Reconciliation Field Mappings com.thortech.xl.dataobj.tcPTY System Configuration com.thortech.xl.dataobj.tcPWP Policy Process Targets com.thortech.xl.dataobj.tcPWR Password Policies com.thortech.xl.dataobj.tcPWT Policy User Targets com.thortech.xl.dataobj.tcRAV Prepopulate Adapter Mappings com.thortech.xl.dataobj.tcRCA Reconciliation Matched Organizations com.thortech.xl.dataobj.tcRCH Reconciliation Event Action History com.thortech.xl.dataobj.tcRCP Reconciliation Event Processes Matched com.thortech.xl.dataobj.tcRCU Reconciliation Event Users Matched com.thortech.xl.dataobj.tcRCX Reconciliation Exceptions com.thortech.xl.dataobj.tcRES Adapter Factory Resources com.thortech.xl.dataobj.tcRGP Role Membership Rules com.thortech.xl.dataobj.tcRML Task Assignment Rules com.thortech.xl.dataobj.tcRPG Reports on roles com.thortech.xl.dataobj.tcRUL Rules Table 12–7 Cont. Data Objects Requiring Explicit InsertUpdateDelete Permissions Data Object Type Entities